compound delegation chain decomposed across CVE-2026-6966 and CVE-2026-6967
details
- Finding IDs
- F-AWS-TOUGH-DELEGATION-CHAIN-001
- GHSA
- GHSA-8m7c-8m39-rv4x
- Status
- fixed publicly
- Reported via
- security contact
- Note
- upstream fixed and publicly released on 2026-04-24 in tough 0.22.0 / tuftool 0.15.0. the reported compound chain is publicly decomposed across GHSA-8m7c-8m39-rv4x / CVE-2026-6966 and GHSA-4v58-8p28-2rq3 / CVE-2026-6967 rather than published as a single bundled advisory.
F-AWS-TOUGH-DELEGATION-CHAIN-001: Verification failures. The compound report concerns metadata/delegation trust checks; related receipts do not create an independent defect count. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-AWS-TOUGH-DELEGATION-CHAIN-001
Security area (1seal assessment): Authorization. The compound report concerns metadata/delegation trust checks; related receipts do not create an independent defect count. Reviewed 24 Sep 2026.